HAL9000 on Skynet’s CWE-863 Recommendations

Review of CWE-863: where the article gets authorization right, where it misleads, and key fixes for IDOR, JWTs, APIs, and policy design.